Texas SB 2610: what changed September 1, 2025

Texas quietly changed the cybersecurity liability conversation on September 1, 2025. SB 2610 — now codified as Chapter 542 of the Texas Business and Commerce Code — created an affirmative defense for businesses that implement a recognized cybersecurity framework. Most of the Texas owners I speak with have never heard of it. The ones who have usually misunderstand what it does.

Here is what the statute actually does.

It establishes a safe harbor. A Texas business that suffers a data breach can present, as an affirmative defense, the fact that it had implemented and was maintaining a written cybersecurity program that reasonably conforms to one of a list of recognized frameworks — NIST CSF, NIST SP 800-171, ISO/IEC 27000, the CIS Critical Security Controls, the FTC Safeguards Rule, and several others. The framework chosen has to scale to the size of the business. The statute defines three tiers: fewer than 20 employees, 20 to 99, and 100 to 249.

That is the structure. Here is the catch most people miss.

The safe harbor only shields the business from punitive or exemplary damages. It does not shield you from actual damages, statutory penalties, regulatory action, or class-action exposure on grounds outside the punitive lane. Plaintiff lawyers can still come after you for the harm caused. What they cannot do — if you can prove framework alignment — is multiply that number for the jury.

That is still valuable. Punitive multipliers are how five-figure incidents become seven-figure verdicts. But it is not we are immune. It is we have a defense.

Two further realities.

First, you do not get the safe harbor by buying a tool. You get it by implementing and maintaining a program. That means written policies, evidence of operation, and the kind of documentation a Texas judge would accept as proof the program was real. A laptop with EDR installed is not a program. A binder with last quarter's review signed off is.

Second, the framework you align to has to fit your size. A 40-person company trying to claim alignment with full NIST CSF will fail the reasonably conforms test on day one. A 40-person company aligning to CIS Implementation Group 1, documenting it, and reviewing it quarterly will pass.

The businesses most exposed under the new statute are the ones that think they are already compliant because their IT provider says they are. The first question to ask is not are we secure — it is what framework are we aligned to, and where is the documentation that would survive a deposition.

Most owners cannot answer that question today. .That is the problem the statute exposes. It is also the gap a competent operator closes.

Previous
Previous

Safe harbor is not insurance

Next
Next

Why we don't call ourselves a managed service provider